Two-Way Security Policy and Audit Log Tracking System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to efficiently inquire, collate, and track security policies and audit logs in real-time, making it difficult to analyze and respond to hacking and security invasion incidents.
Innovation Solution
A system and method that utilize a security policy setting unit, security software agent, audit log collection unit, and two-way inquiry tracking unit to record and manage security policies and audit logs with unique policy identification information, enabling two-way inquiry, collation, and tracking of security policies and audit logs in real-time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If log files are collected and stored without policy association, then log storage is simple, but it becomes impossible to analyze the cause of security incidents by comparing logs with security policies
Solution Approach 1:
The system performs preliminary action by associating policy identification information with audit logs at the time of log generation, rather than attempting to associate them later during analysis. The security policy setting unit assigns unique policy IDs to policies, and the security software agent includes these IDs in generated audit logs, ensuring policy-log associations are established before any analysis occurs.
Solution Approach 2:
The system introduces policy identification information as an intermediary element that bridges security policies and audit logs. This intermediary consists of unique policy IDs assigned to policies and included in corresponding audit logs, enabling efficient association without direct complex linking between entire policy documents and log files.
2Measurement precision
If managers analyze log files by comparing with security policies one by one, then analysis is thorough, but it takes a long time and is economically inefficient
Solution Approach 1:
The system creates a copy of the policy identification information within the audit log itself. Instead of requiring managers to access and compare entire security policy documents, the unique policy ID embedded in each audit log serves as a compact reference that can be quickly matched against stored policy information, dramatically reducing analysis time while maintaining accuracy.
Solution Approach 2:
The system performs preliminary organization of policy-log associations by embedding policy IDs in audit logs during log generation. This preliminary structuring eliminates the need for time-consuming manual comparison during incident analysis, as the associations are already established and can be retrieved instantly.
3Adaptability or versatility
If the system does not track policy changes over time, then the system is simpler, but it cannot inquire and confirm past security policies and logs that were set in the past
Solution Approach 1:
The system performs preliminary action by recording policy identification information along with policy configuration details in the integrated security policy history database whenever policies are generated or changed. This historical recording enables retrospective inquiry of past policies and their associated logs without adding complex temporal tracking mechanisms during operation.
Solution Approach 2:
The policy identification information serves as a stable intermediary that links past security policies with their corresponding audit logs across different time periods. By including policy IDs in both the history database and audit logs, the system enables temporal associations without requiring complex time-based tracking of policy changes.
4Quantity of substance
If various security related logs increase exponentially, then comprehensive logging is achieved, but it becomes very difficult to clearly compare and analyze the policy generating the corresponding log
Solution Approach 1:
The system embeds a compact copy of the policy identification (unique policy ID) directly within each audit log. This allows exponential growth in log volume while maintaining constant-time policy identification, as managers only need to match the small policy ID field against the integrated security policy history database rather than analyzing entire policy documents for each log entry.
Solution Approach 2:
The system extracts the essential policy identification element (unique policy ID) from the full security policy and places it within the audit log. This extraction creates a lightweight reference that enables efficient filtering and analysis of large volumes of logs by policy, without requiring the full policy content to be stored or processed with each log entry.
Data Source
AI summary
The present invention relates to a security policy and audit log two-way inquiry, collation, and tracking system and method capable of effectively inquiring and confirming various pieces of log information generated due to setting and change of various security policies, and capable of inquiring and confirming a security policy related to log information based on the collected log information. According to the present invention, it is possible to inquire, collate, and track logs generated and recorded by the various security policies, it is possible to inquire, collate, and track the security policy applied to the collected log, and it is possible to inquire, collate, and track the security policy and the log in two ways and in real time.


